{"id":"CVE-2026-16570","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-16570","summary":"The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string parameters it reflects back on one of its admin pages, allowing attackers…","details":"The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string parameters it reflects back on one of its admin pages, allowing attackers to perform Reflected Cross-Site Scripting attacks against logged-in users such as administrators who are tricked into opening a crafted link.","published":"2026-08-19T06:00:17.019Z","modified":"2026-08-19T06:00:17.019Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"EXPLOIT","url":"https://wpscan.com/vulnerability/25c42ca3-ff25-4b43-a712-2876398d82ab/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-19T06:00:17.019Z"}}